CVE-2026-98338: wifi: cfg80211: ibss: ref BSS entry for joined event

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: ibss: ref BSS entry for joined event

When the IBSS is joined, we only record the BSSID/channel in the event and look up the BSS entry when processing it. However, that's racy, e.g. a new scan with NL80211SCANFLAGFLUSH can remove it, causing a warning in the event work:

!bss WARNING: net/wireless/ibss.c:37 at cfg80211ibssjoined+0x3d3/0x440 Workqueue: cfg80211 cfg80211eventwork cfg80211processwdevevents+0x39f/0x5b0 net/wireless/util.c:1144 cfg80211processrdevevents+0xa1/0x110 net/wireless/util.c:1179 cfg80211eventwork+0x2f/0x40 net/wireless/core.c:393

Do the lookup early (the driver is expected to only join an IBSS that has a BSS entry) and keep a reference to it.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:43 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required to trigger the issue?

A device must join an IBSS network, and a subsequent scan using NL80211_SCAN_FLAG_FLUSH must remove the associated BSS entry before the queued joined event is processed. The race then causes the event work to find no BSS entry and emit a kernel warning.

2

Which systems are most likely to be exposed?

Systems using Linux kernel Wi-Fi functionality with cfg80211 and participating in IBSS (ad-hoc) networks are relevant. The issue is specifically tied to IBSS join event handling rather than ordinary infrastructure-mode Wi-Fi operation.

3

How can I identify that the issue has occurred?

Kernel logs may contain a warning beginning with "!bss WARNING: net/wireless/ibss.c:37" and a stack trace involving __cfg80211_ibss_joined, cfg80211_process_wdev_events, and cfg80211_event_work.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203